useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
2006-05-28T23:02:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 3.7 (LOW)
AV:L/AC:H/Au:N/C:P/I:P/A:P
1.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | debian | shadow | ≤ 4.0.7 | Yes |
Application | debian | shadow | 4.0.0 | Yes |
Application | debian | shadow | 4.0.1 | Yes |
Application | debian | shadow | 4.0.2 | Yes |
Application | debian | shadow | 4.0.4 | Yes |
Application | debian | shadow | 4.0.4.1 | Yes |
Application | debian | shadow | 4.0.5 | Yes |
Application | debian | shadow | 4.0.6 | Yes |